HIGH
CVE-2026-67687
CVSS
8.8
Description
Insecure Permissions vulnerability in ics-park v.2.0 allows a remote attacker to escalate privileges via the /system/role/save endpoint in RoleController.java and system/user/update endpoint in UserController.java
Weakness (CWE)
CWE-284
Improper Access Control
EPSS Score
0.45%
Probability of exploitation in next 30 days
38.5th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.